CVE-2026-2864

Source
https://cve.org/CVERecord?id=CVE-2026-2864
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2864.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2864
Published
2026-02-21T07:32:07Z
Modified
2026-10-08T02:50:46Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
feng_ha_ha/megagao ssm-erp/production_ssm PictureController.java pictureDelete path traversal
Details

A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. This affects the function pictureDelete of the file PictureController.java. Such manipulation of the argument picName leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. This product is distributed under two entirely different names. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2864.json"
}
References

Affected packages

Git / github.com/megagao/production_ssm

Affected ranges

Type
GIT
Repo
https://github.com/megagao/production_ssm
Events

Affected versions

Other
4288d53bd35757b27f2d070057aefb2c07bdd097

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2864.json"